Hello, is there any way to have a source_hostname instead of source_ip. I am looking to monitor traffic data and it seems there is only a choice by IP but hostname would be more useful since we wouldn't have to keep track of every IP.
Thanks,
Kenny
Hello, is there any way to have a source_hostname instead of source_ip. I am looking to monitor traffic data and it seems there is only a choice by IP but hostname would be more useful since we wouldn't have to keep track of every IP.
Thanks,
Kenny
Are you referring to the monitoring module that comes with X-Pack?
What hostname would you like to see? What protocols are you talking about here?
There is a reverse lookup filter in Logstash that can add hostnames to events.
how can this be done through logstash? is there a way to do this through elasticsearch as i am not sending any packetbeats to logstash.
You need Logstash for that. See https://www.elastic.co/guide/en/logstash/current/plugins-filters-dns.html
ok, ill give this a shot thanks!
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.